Skip to content
Tip 2 Cloud

Free study guides, practices test, sample questions

Primary Navigation Menu
Menu
  • Home
  • About us
  • Contact

Security Specialty (Page 8)

Home » Security Specialty

How should the Security Engineer collect a memory dump of the EC2 instance for forensic analysis?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

After multiple compromises of its Amazon EC2 instances, a company’s Security Officer is mandating that memory dumps of compromised instances be captured for further analysis.A Security Engineer just received an EC2 abuse notification report from AWS stating that an EC2 instance running the most recent WindowsServer 2019 Base AMI is compromised.How should the Security Engineer collect a memory dump of the EC2 instance for forensic analysis?Read More →

How can the Administrator restrict usage of member root user accounts across the organization?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A Security Administrator is restricting the capabilities of company root user accounts.The company uses AWS Organizations and has enabled it for all feature sets, including consolidated billing.The top-level account is used for billing and administrative purposes, not for operational AWS resource purposes.How can the Administrator restrict usage of member root user accounts across the organization?Read More →

The mail application should be configured to connect to which of the following endpoints and corresponding ports?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A Systems Engineer has been tasked with configuring outbound mail through Simple Email Service (SES) and requires compliance with current TLS standards.The mail application should be configured to connect to which of the following endpoints and corresponding ports?Read More →

What mechanism will allow the company to implement all required network rules without incurring additional cost?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A company has complex connectivity rules governing ingress, egress, and communications between Amazon EC2 instances.The rules are so complex that they cannot be implemented within the limits of the maximum number of security groups and network access control lists (network ACLs).What mechanism will allow the company to implement all required network rules without incurring additional cost?Read More →

Which configurations will support these requirements?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A Security Administrator has a website hosted in Amazon S3.The Administrator has been given the following requirements:✑ Users may access the website by using an Amazon CloudFront distribution.✑ Users may not access the website directly by using an Amazon S3 URL.Which configurations will support these requirements? (Choose two.)Read More →

Which of the following approaches achieve this requirement?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A company requires that IP packet data be inspected for invalid or malicious content.Which of the following approaches achieve this requirement? (Choose two.)Read More →

How should the company accomplish this at the LOWEST cost?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A company needs to migrate several applications to AWS.This will require storing more than 5,000 credentials.To meet compliance requirements, the company will use its existing password management system for key rotation, auditing, and integration with third-party secrets containers.The company has a limited budget and is seeking the most cost-effective solution that is still secure.How should the company accomplish this at the LOWEST cost?Read More →

Which combination of steps should the security engineer take to meet these requirements?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A company’s policies require that code be validated to ensure that the code has not been altered before invocation.A security engineer needs to update code in an AWS Lambda function.The developer has finalized the code and has stored the code in an Amazon S3 bucket.Which combination of steps should the security engineer take to meet these requirements? (Choose two.)Read More →

Which combination of steps will meet these requirements?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A company in France uses Amazon Cognito with the Cognito Hosted UI as an identity broker for sign-in and sign-up processes.The company is marketing an application and expects that all the application’s users will come from France.When the company launches the application, the company’s security team observes fraudulent sign-ups for the application.Most of the fraudulent registrations are from users outside of France.The security team needs a solution to perform custom validation at sign-up.Based on the results of the validation, the solution must accept or deny the registration request.Which combination of steps will meet these requirements? (Choose two.)Read More →

Which combination of steps should the company take next to meet this requirement?

2025-10-14
By: study aws cloud
In: SCS-C01
With: 1 Comment

A company has an AWS WAF web ACL.According to a new compliance requirement, the company must configure comprehensive logging of all web ACL requests.The company has created an Amazon S3 bucket to store the logs.Which combination of steps should the company take next to meet this requirement? (Choose two.)Read More →

Posts pagination

Previous 1 … 7 8 9 … 41 Next

Recent Posts

  • What should a solutions architect do to meet these requirements?
  • What should a solutions architect do to meet these requirements?
  • Which solution will meet these requirements?
  • What should be done to secure the root user?
  • What should the solutions architect do to maximize reliability of the application’s infrastructure?

Categories

  • CLF-C01
  • CLF-C02
  • DBS-C01
  • DOP-C01
  • DOP-C02
  • DVA-C01
  • DVA-C02
  • MLS-C01
  • SAA-C02
  • SAA-C03
  • SAP-C01
  • SAP-C02
  • SCS-C01
  • SOA-C01
  • SOA-C02

© 2025. Tip2Cloud doesn't offer any real exam questions. All questions & answers were supported by AI.